CVE-2026-82305 PUBLISHED

YITH WooCommerce Wishlist < 4.18.1 - Unauthenticated Arbitrary Wishlist Rename via change_wishlist_title

Assigner: WPScan
Reserved: 28.08.2026 Published: 11.09.2026 Updated: 11.09.2026

The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site.

Product Status

Vendor Unknown
Product YITH WooCommerce Wishlist
Versions Default: unaffected
  • affected from 0 to 4.18.1 (excl.)

Credits

  • Abdullah Kareem finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE